US2024370593A1PendingUtilityA1

NUTS: eNcrypted Userdata Transit and Storage

Assignee: NUTS HOLDINGS LLCPriority: Sep 15, 2016Filed: Jul 16, 2024Published: Nov 7, 2024
Est. expirySep 15, 2036(~10.1 yrs left)· nominal 20-yr term from priority
Inventors:Yoon Ho Auh
H04L 63/0442H04L 63/0281H04L 9/3247H04L 9/3242H04L 9/0637G06F 21/6227H04L 9/14H04L 9/0861H04L 9/085H04L 9/0643G06F 21/602H04L 9/3226G06F 16/258G06F 21/78H04L 63/0428H04L 9/40
82
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A lock node for storing data and a protected storage unit. The lock node includes an input section which provides a plurality of key maps, each corresponding to one of a plurality of primary keys, respectively, applied to the input section, each key map including at least one main key, a variable lock section producing a derived key from a logical operation on the main keys corresponding to the primary keys applied to the input section, and an output section producing the data in response to the derived key.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method of processing data comprising:
 at least one processor accessing a data storage unit, the data storage unit providing the identity of at least one application that will operate on the data in the data storage unit;   the at least one processor retrieving the at least one application from a collection of applications; and   the at least one processor using the at least one application to operate on the data in the data storage unit.   
     
     
         2 . The method of  claim 1 , wherein the at least one application performs at least one of the following:
 reading the data in the data storage unit;   writing the data to the data storage unit or to a different data storage unit;   causing the data to be displayed;   converting the data from one version to another version;   applying a cryptographic operation on the data;   operating on the information associated with the data in the data storage unit; and   transmitting over a network to another at least one processor at least one of:
 the data in the data storage unit, 
 a subset of the data in the data storage unit, 
 a derivative of the data in the data storage unit, 
 a cryptographic output of the data in the data storage unit, 
 metadata of the data in the data storage unit, and 
 metadata of the data storage unit. 
   
     
     
         3 . The method of  claim 1 , wherein the data includes another at least one application. 
     
     
         4 . The method of  claim 1 , wherein the data storage unit is a protected data storage unit. 
     
     
         5 . The method of  claim 4 , wherein the protected data storage unit is a nut comprising:
 at least one memory; and   a plurality of lock nodes stored in the at least one memory, each of the lock nodes comprising:
 an input section including a plurality of key maps, each of the key maps being encrypted with a corresponding one of a plurality of primary keys, respectively, the key maps including a plurality of main keys; 
 a variable lock section including an encrypted derived key, the encrypted derived key configured to be decrypted with a key derived from a logical operation on the plurality of main keys corresponding to the plurality of primary keys applied to the input section; and 
 an output section including encrypted data, the encrypted data configured to be decrypted with the derived key; 
   at least one keyhole lock node of the plurality of lock nodes including a key map for each of the primary keys including at least one access attribute key, the at least one access attribute key configured to provide role based access control based on the corresponding primary key within the protected data storage unit; and   at least one of the lock nodes providing an output key which is a primary key for another of the lock nodes;   wherein each key map includes at least one access attribute key, the input section further including at least one encrypted access role key, the at least one encrypted access role key configured to be decrypted by the at least one access attribute key, the at least one access role key configured to enable at least one operation on the data, wherein the at least one access role key is based on permissions associated with the designated primary key resulting in the particular key map.   
     
     
         6 . The method of  claim 5 , further comprising combining the at least one access role key in a logical operation with other provided at least one access role keys to form a union of all the defined operations permitted on the data. 
     
     
         7 . The method of  claim 5 , wherein the input section of one of the lock nodes provides at least one access key for another of the lock nodes. 
     
     
         8 . The method of  claim 5 , wherein at least one key map for one of the lock nodes includes at least one stratum key, the at least one stratum key decrypting a different key map for at least one lock node different from the one lock node. 
     
     
         9 . The method of  claim 8 , wherein the at least one stratum key and the input sections of the lock nodes in the storage unit control which lock nodes within the storage unit are accessible for the particular designated primary key. 
     
     
         10 . The method of  claim 5 , wherein the output section of at least one lock node of the storage unit stores at least one log section storing data related to accesses of the protected data storage unit across a plurality of different applications. 
     
     
         11 . The method of  claim 10 , wherein the at least one log is stored in encrypted form. 
     
     
         12 . The method of  claim 10 , wherein at least one parameter stored in the protected data storage unit controls at least one of:
 what is logged and what is not logged;   a level of detail in the at least one log,   a type of log to produce, and   a method of producing a log entry.   
     
     
         13 . The method of  claim 12 , wherein the type of log comprises at least one of:
 log entries involving processing events involving the protected data storage unit, and   historical revision entries involving the data in the protected data storage unit.   
     
     
         14 . The method of  claim 1 , wherein the at least one application is stored in a protected data storage unit. 
     
     
         15 . The method of  claim 14 , wherein the protected data storage unit is a nut comprising:
 at least one memory; and   a plurality of lock nodes stored in the at least one memory, each of the lock nodes comprising:
 an input section including a plurality of key maps, each of the key maps being encrypted with a corresponding one of a plurality of primary keys, respectively, the key maps including a plurality of main keys; 
 a variable lock section including an encrypted derived key, the encrypted derived key configured to be decrypted with a key derived from a logical operation on the plurality of main keys corresponding to the plurality of primary keys applied to the input section; and 
 an output section including encrypted data, the encrypted data configured to be decrypted with the derived key; 
   at least one keyhole lock node of the plurality of lock nodes including a key map for each of the primary keys including at least one access attribute key, the at least one access attribute key configured to provide role based access control based on the corresponding primary key within the protected data storage unit; and   at least one of the lock nodes providing an output key which is a primary key for another of the lock nodes;   wherein each key map includes at least one access attribute key, the input section further including at least one encrypted access role key, the at least one encrypted access role key configured to be decrypted by the at least one access attribute key, the at least one access role key configured to enable at least one operation on the data, wherein the at least one access role key is based on permissions associated with the designated primary key resulting in the particular key map.   
     
     
         16 . The method of  claim 15 , further comprising combining the at least one access role key in a logical operation with other provided at least one access role keys to form a union of all the defined operations permitted on the data. 
     
     
         17 . The method of  claim 15 , wherein the input section of one of the lock nodes provides at least one access key for another of the lock nodes. 
     
     
         18 . The method of  claim 15 , wherein at least one key map for one of the lock nodes includes at least one stratum key, the at least one stratum key decrypting a different key map for at least one lock node different from the one lock node. 
     
     
         19 . The method of  claim 18 , wherein the at least one stratum key and the input sections of the lock nodes in the storage unit control which lock nodes within the storage unit are accessible for the particular designated primary key. 
     
     
         20 . The method of  claim 15 , wherein the output section of at least one lock node of the storage unit stores at least one log section storing data related to accesses of the protected data storage unit across a plurality of different applications. 
     
     
         21 . The method of  claim 20 , wherein the at least one log is stored in encrypted form. 
     
     
         22 . The method of  claim 20 , wherein at least one parameter stored in the protected data storage unit controls at least one of:
 what is logged and what is not logged;   a level of detail in the at least one log,   a type of log to produce, and   a method of producing a log entry.   
     
     
         23 . The method of  claim 22 , wherein the type of log comprises at least one of:
 log entries involving processing events involving the protected data storage unit, and   historical revision entries involving the data in the protected data storage unit.

Join the waitlist — get patent alerts

Track US2024370593A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.